Security at ZiaPilot AI
Last updated June 6, 2026
We take protecting your data and your customers' data seriously. Here's how we keep the platform secure.
01Encryption
All traffic is encrypted in transit with TLS. Sensitive credentials such as API keys and integration tokens are encrypted at rest.
02Tenant isolation
Every restaurant workspace is isolated with its own scoped data boundary, so one account can never read another account's conversations, customers, or settings.
03Access control
Dashboard access is protected by authenticated sessions with role-based permissions. Internal access to production data is restricted, logged, and granted on a least-privilege basis.
- Role-based admin and staff permissions.
- Audit logging of sensitive actions.
- Rate limiting and security headers on every request.
04Payments
Payments are handled by Stripe, a PCI-DSS Level 1 provider. We never store full card numbers on our servers.
05Reliability & backups
Data is backed up regularly and the platform is monitored for availability and anomalies so issues are caught early.
06Responsible disclosure
Found a vulnerability? We appreciate responsible disclosure. Email [email protected] with details and we'll investigate promptly.
Turn chats into catering orders
Start a 7-day full trial (no card needed). See ZiaPilot AI answer menu questions and capture orders on your site and WhatsApp.